CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-29228

    Last Modified: 23 Apr 2025

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 9 Jun 2022
    5.9
    Medium

    CVE-2022-29224

    Last Modified: 23 Apr 2025

    Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can “hold” (prevent removal) upstream hosts obtained via service discovery until configured active health checking fails. If an attacker controls an upstream host and also controls service discovery of that host (via DNS, the EDS API, etc.), an attacker can crash Envoy by forcing removal of the host from service discovery, and then failing the gRPC health check request. This will crash Envoy via a null pointer dereference. Users are advised to upgrade to resolve this vulnerability. Users unable to upgrade may disable gRPC health checking and/or replace it with a different health checking type as a mitigation.

    Published: 9 Jun 2022
    10
    Critical

    CVE-2022-29226

    Last Modified: 23 Apr 2025

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2022-29227

    Last Modified: 23 Apr 2025

    Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request Envoy sends a local reply when the redirect headers are processed, the downstream state indicates that the downstream stream is not complete. On sending the local reply, Envoy will attempt to reset the upstream stream, but as it is actually complete, and deleted, this result in a use-after-free. Users are advised to upgrade. Users unable to upgrade are advised to disable internal redirects if crashes are observed.

    Published: 9 Jun 2022
    9.1
    Critical

    CVE-2022-31827

    Last Modified: 21 Nov 2024

    MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.

    Published: 9 Jun 2022
    9.1
    Critical

    CVE-2022-31830

    Last Modified: 21 Nov 2024

    Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

    Published: 9 Jun 2022
    9.1
    Critical

    CVE-2022-31393

    Last Modified: 21 Nov 2024

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.

    Published: 9 Jun 2022
    9.1
    Critical

    CVE-2022-31390

    Last Modified: 21 Nov 2024

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.

    Published: 9 Jun 2022
    9.1
    Critical

    CVE-2022-31386

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.

    Published: 9 Jun 2022
    3.5
    Low

    CVE-2019-25070

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-135125 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 9 Jun 2022
    5.3
    Medium

    CVE-2019-25069

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Axios Italia Axios RE 1.7.0/7.0.0. This issue affects some unknown processing of the component Error Message Handler. The manipulation leads to information disclosure (ASP.NET). The attack may be initiated remotely.

    Published: 9 Jun 2022
    6.3
    Medium

    CVE-2019-25068

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0. This vulnerability affects unknown code of the file REDefault.aspx of the component Connection Handler. The manipulation of the argument DBIDX leads to privilege escalation. The attack can be initiated remotely.

    Published: 9 Jun 2022
    6.3
    Medium

    CVE-2019-25066

    Last Modified: 15 Apr 2025

    A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    6.3
    Medium

    CVE-2019-25065

    Last Modified: 15 Apr 2025

    A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jun 2022
    4.3
    Medium

    CVE-2019-25064

    Last Modified: 15 Apr 2025

    A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    8.1
    High

    CVE-2021-40668

    Last Modified: 21 Nov 2024

    The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.

    Published: 9 Jun 2022
    6.4
    Medium

    CVE-2022-26362

    Last Modified: 21 Nov 2024

    x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race condition, whereby a safely TLB flush is issued too early and creates a window where the guest can re-establish the read/write mapping before writeability is prohibited.

    Published: 9 Jun 2022
    6.7
    Medium

    CVE-2022-26364

    Last Modified: 21 Nov 2024

    x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, Xen's safety logic doesn't account for CPU-induced cache non-coherency; cases where the CPU can cause the content of the cache to be different to the content in main memory. In such cases, Xen's safety logic can incorrectly conclude that the contents of a page is safe.

    Published: 9 Jun 2022
    6.7
    Medium

    CVE-2022-26363

    Last Modified: 21 Nov 2024

    x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, Xen's safety logic doesn't account for CPU-induced cache non-coherency; cases where the CPU can cause the content of the cache to be different to the content in main memory. In such cases, Xen's safety logic can incorrectly conclude that the contents of a page is safe.

    Published: 9 Jun 2022
    5.4
    Medium

    CVE-2021-40610

    Last Modified: 21 Nov 2024

    Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.

    Published: 9 Jun 2022
    8
    High

    CVE-2022-2037

    Last Modified: 21 Nov 2024

    Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

    Published: 9 Jun 2022
    7.3
    High

    CVE-2016-15002

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-29920

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-29896

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Jun 2022
    5.4
    Medium

    CVE-2022-2036

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.

    Published: 9 Jun 2022
    9.8
    Critical

    CVE-2022-1986

    Last Modified: 21 Nov 2024

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

    Published: 9 Jun 2022
    8.8
    High

    CVE-2022-30075

    Last Modified: 21 Nov 2024

    In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2022-31649

    Last Modified: 21 Nov 2024

    ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

    Published: 9 Jun 2022
    5.5
    Medium

    CVE-2022-25804

    Last Modified: 21 Nov 2024

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unprivileged local attacker to read the encrypted dbuser and dbpassword values for the UMS superuser.

    Published: 9 Jun 2022
    6.5
    Medium

    CVE-2022-25805

    Last Modified: 21 Nov 2024

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_load_mgt_tree command allows an attacker (who can intercept or inspect traffic between an authenticated UMS client and server) to compromise those LDAP bind credentials.

    Published: 9 Jun 2022
    8.8
    High

    CVE-2022-25806

    Last Modified: 21 Nov 2024

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.

    Published: 9 Jun 2022
    5.5
    Medium

    CVE-2022-25807

    Last Modified: 21 Nov 2024

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted LDAP bind credentials, to decrypt those credentials using a static 8-byte DES key.

    Published: 9 Jun 2022
    6.1
    Medium

    CVE-2022-32195

    Last Modified: 21 Nov 2024

    Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32808

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    8.8
    High

    CVE-2021-40961

    Last Modified: 21 Nov 2024

    CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2022-31043

    Last Modified: 23 Apr 2025

    Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we should not forward the `Authorization` header on. This is much the same as to how we don't forward on the header if the host changes. Prior to this fix, `https` to `http` downgrades did not result in the `Authorization` header being removed, only changes to the host. Affected Guzzle 7 users should upgrade to Guzzle 7.4.4 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.7 or 7.4.4. Users unable to upgrade may consider an alternative approach which would be to use their own redirect middleware. Alternately users may simply disable redirects all together if redirects are not expected or required.

    Published: 9 Jun 2022
    9.8
    Critical

    CVE-2022-32272

    Last Modified: 21 Nov 2024

    OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32667

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32669

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32670

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32671

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32672

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32673

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32674

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32675

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32677

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32678

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022
    —
    Unknown

    CVE-2022-32679

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 9 Jun 2022